Vulnerabilities in Apache Software Foundation

2,378 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-24070—Apache Subversion mod_dav_svn is vulnerable to memory corruptionEPSS 9.5%CVE-2024-56337CRITICALApache Tomcat: RCE due to TOCTOU issue in JSP compilation - CVE-2024-50379 mitigation was incompleteEPSS 9.0%CVE-2018-8026—This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (EPSS 9.0%CVE-2017-15691—In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, EPSS 9.0%CVE-2018-17190—In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'woEPSS 8.8%CVE-2017-9793—The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerableEPSS 8.8%CVE-2019-0197—A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 oEPSS 8.7%CVE-2021-26291—block repositories using http by defaultEPSS 8.7%CVE-2025-27533MEDIUMApache ActiveMQ: Unchecked buffer length can cause excessive memory allocationEPSS 8.7%CVE-2018-1327—The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request witEPSS 8.6%CVE-2018-11761—In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expanEPSS 8.6%CVE-2018-8039—It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.EPSS 8.5%CVE-2018-8012—No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha throuEPSS 8.5%CVE-2022-25762—Response mix-up with WebSocket concurrent send and closeEPSS 8.4%CVE-2017-12627—In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain EPSS 8.4%CVE-2024-42323HIGHApache HertzBeat: RCE by snakeYaml deser load malicious xmlEPSS 8.3%CVE-2016-6796—A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 toEPSS 8.3%CVE-2017-5650—In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams asEPSS 8.3%CVE-2017-9804—In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidaEPSS 8.2%CVE-2016-6795—In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will beEPSS 8.2%